PT-2024-5937 · Haproxy+2 · Haproxy+2

Published

2024-09-04

·

Updated

2025-09-11

·

CVE-2024-45506

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions HAProxy versions 2.9.x through 2.9.9 HAProxy versions 3.0.x through 3.0.3 HAProxy versions 3.1.x through 3.1-dev6
Description The issue is related to a remote denial of service vulnerability in HAProxy, which can be exploited under certain conditions. This vulnerability has been exploited in the wild. The vulnerability is caused by an endless loop when handling HTTP/2 zero-copy forwarding, which can lead to service disruptions and system crashing.
Recommendations For HAProxy versions 2.9.x through 2.9.9, update to version 2.9.10 or later. For HAProxy versions 3.0.x through 3.0.3, update to version 3.0.4 or later. For HAProxy versions 3.1.x through 3.1-dev6, update to a version later than 3.1-dev6. As a temporary workaround, consider disabling HTTP/2 zero-copy forwarding until a patch is available.

Fix

DoS

Infinite Loop

Improper Resource Release

Weakness Enumeration

Related Identifiers

AZL-48668
BDU:2024-06744
BIT-HAPROXY-2024-45506
CVE-2024-45506
OESA-2024-2130
OPENSUSE-SU-2024:14307-1

Affected Products

Astra Linux
Haproxy
Red Os